MAL-2026-12117

    Dashboard / Malicious Package / MAL-2026-12117

    MAL-2026-12117

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in 1239i32049i (npm)

    Details: Source: amazon-inspector (6c99f6d077df7b1209fb59dafa8641b14b3947d321379bc6ad22f2660d3d4c7b) Package declares a postinstall script that runs dist/index.js, the sole shipped file, which is heavily obfuscated with javascript-obfuscator (rotated string array, _0xNNNN identifiers, control-flow dispatch). At install time it reads process.env.P, issues an HTTPS GET to https://dropper-crm.vercel.app/api/payload/<P>, base64-decodes the response body, and executes it via new Function('require', decoded), granting the remote endpoint arbitrary code execution with require access on the installing machine. The package name is a numeric string with no documented functionality, no README, and no legitimate purpose beyond delivery of the remote payload.

    Affected packages

    Package

    Name: 1239i32049i

    Purl: pkg:npm/1239i32049i

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    0.1.0
    MAL-2026-12117 | CVE-DB